Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-20022 KEV |
|
[KEV] Unrestricted File Upload in Sonicwall email-security (CVE-2021-20022)
vulnerability in Sonicwall email-security (CVE-2021-20022). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-20023 KEV |
|
[KEV] Path Traversal in Sonicwall email-security (CVE-2021-20023)
path traversal in Sonicwall email-security (CVE-2021-20023). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2020-6819 KEV |
|
[KEV] Vulnerability in Mozilla firefox-and-thunderbird (CVE-2020-6819)
vulnerability in Mozilla firefox-and-thunderbird (CVE-2020-6819). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-6820 KEV |
|
[KEV] Vulnerability in Mozilla firefox-and-thunderbird (CVE-2020-6820)
vulnerability in Mozilla firefox-and-thunderbird (CVE-2020-6820). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-17026 KEV |
|
[KEV] Vulnerability in Mozilla firefox-and-thunderbird (CVE-2019-17026)
vulnerability in Mozilla firefox-and-thunderbird (CVE-2019-17026). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2017-9805 KEV |
|
[KEV] Unsafe Deserialization in Apache struts (CVE-2017-9805)
vulnerability in Apache struts (CVE-2017-9805). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-42013 KEV |
|
[KEV] Path Traversal in Apache http-server (CVE-2021-42013)
path traversal in Apache http-server (CVE-2021-42013). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2021-41773 KEV |
|
[KEV] Path Traversal in Apache http-server (CVE-2021-41773)
path traversal in Apache http-server (CVE-2021-41773). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-0211 KEV |
|
[KEV] Use-After-Free in Apache http-server (CVE-2019-0211)
vulnerability in Apache http-server (CVE-2019-0211). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2016-4437 KEV |
|
[KEV] Vulnerability in Apache shiro (CVE-2016-4437)
vulnerability in Apache shiro (CVE-2016-4437). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-17558 KEV |
|
[KEV] Vulnerability in Apache solr (CVE-2019-17558)
vulnerability in Apache solr (CVE-2019-17558). Successful exploitation can lead to full system takeover. Exploitable via ``params.resource.loader.enabled``. Listed in CISA KEV — actively exploited.
|
| CVE-2020-17530 KEV |
|
[KEV] Vulnerability in Apache struts (CVE-2020-17530)
vulnerability in Apache struts (CVE-2020-17530). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2017-5638 KEV |
|
[KEV] Vulnerability in Apache struts (CVE-2017-5638)
vulnerability in Apache struts (CVE-2017-5638). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-11776 KEV |
|
[KEV] Vulnerability in Apache struts (CVE-2018-11776)
vulnerability in Apache struts (CVE-2018-11776). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-25213 KEV |
|
[KEV] Unrestricted File Upload in Wordpress file-manager-plugin (CVE-2020-25213)
vulnerability in Wordpress file-manager-plugin (CVE-2020-25213). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-11738 KEV |
|
[KEV] Path Traversal in Wordpress snap-creek-duplicator-plugin (CVE-2020-11738)
path traversal in Wordpress snap-creek-duplicator-plugin (CVE-2020-11738). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-9978 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Wordpress social-warfare-plugin (CVE-2019-9978)
cross-site scripting in Wordpress social-warfare-plugin (CVE-2019-9978). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-7600 KEV |
|
[KEV] Vulnerability in drupal (CVE-2018-7600)
vulnerability in drupal (CVE-2018-7600). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2019-2215 KEV |
|
[KEV] Use-After-Free in android (CVE-2019-2215)
vulnerability in android (CVE-2019-2215). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-0041 KEV |
|
[KEV] Vulnerability in android (CVE-2020-0041)
vulnerability in android (CVE-2020-0041). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-15752 KEV |
|
[KEV] Vulnerability in Docker desktop-community-edition (CVE-2019-15752)
vulnerability in Docker desktop-community-edition (CVE-2019-15752). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-15505 KEV |
|
[KEV] Vulnerability in Ivanti mobileiron-multiple-products (CVE-2020-15505)
vulnerability in Ivanti mobileiron-multiple-products (CVE-2020-15505). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22893 KEV |
|
[KEV] Authentication Bypass in Ivanti pulse-connect-secure (CVE-2021-22893)
authentication bypass in Ivanti pulse-connect-secure (CVE-2021-22893). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8243 KEV |
|
[KEV] Code Injection in Ivanti pulse-connect-secure (CVE-2020-8243)
code injection in Ivanti pulse-connect-secure (CVE-2020-8243). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22900 KEV |
|
[KEV] Code Injection in Ivanti pulse-connect-secure (CVE-2021-22900)
code injection in Ivanti pulse-connect-secure (CVE-2021-22900). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22894 KEV |
|
[KEV] Code Injection in Ivanti pulse-connect-secure (CVE-2021-22894)
code injection in Ivanti pulse-connect-secure (CVE-2021-22894). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8260 KEV |
|
[KEV] Unrestricted File Upload in Ivanti pulse-connect-secure (CVE-2020-8260)
vulnerability in Ivanti pulse-connect-secure (CVE-2020-8260). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22899 KEV |
|
[KEV] Command Injection in Ivanti pulse-connect-secure (CVE-2021-22899)
command injection in Ivanti pulse-connect-secure (CVE-2021-22899). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-11510 KEV |
|
[KEV] Path Traversal in Ivanti pulse-connect-secure (CVE-2019-11510)
path traversal in Ivanti pulse-connect-secure (CVE-2019-11510). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-11539 KEV |
|
[KEV] OS Command Injection in Ivanti pulse-connect-secure-and-pulse-policy-secure (CVE-2019-11539)
OS command injection in Ivanti pulse-connect-secure-and-pulse-policy-secure (CVE-2019-11539). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-29557 KEV |
|
[KEV] Buffer Overflow in D-link dir-825-r1-devices (CVE-2020-29557)
vulnerability in D-link dir-825-r1-devices (CVE-2020-29557). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-25506 KEV |
|
[KEV] OS Command Injection in D-link dns-320-device (CVE-2020-25506)
OS command injection in D-link dns-320-device (CVE-2020-25506). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3452 KEV |
|
[KEV] Vulnerability in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2020-3452)
vulnerability in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2020-3452). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3580 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2020-3580)
cross-site scripting in Cisco adaptive-security-appliance-asa-and-firepower-threat-defense-ftd (CVE-2020-3580). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-1497 KEV |
|
[KEV] OS Command Injection in Cisco hyperflex-hx (CVE-2021-1497)
OS command injection in Cisco hyperflex-hx (CVE-2021-1497). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-1498 KEV |
|
[KEV] OS Command Injection in Cisco hyperflex-hx (CVE-2021-1498)
OS command injection in Cisco hyperflex-hx (CVE-2021-1498). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-0171 KEV |
|
[KEV] Vulnerability in Cisco ios-and-ios-xe (CVE-2018-0171)
vulnerability in Cisco ios-and-ios-xe (CVE-2018-0171). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3118 KEV |
|
[KEV] Vulnerability in Cisco ios-xr (CVE-2020-3118)
vulnerability in Cisco ios-xr (CVE-2020-3118). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3566 KEV |
|
[KEV] Vulnerability in Cisco ios-xr (CVE-2020-3566)
vulnerability in Cisco ios-xr (CVE-2020-3566). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3569 KEV |
|
[KEV] Vulnerability in Cisco ios-xr (CVE-2020-3569)
vulnerability in Cisco ios-xr (CVE-2020-3569). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-3161 KEV |
|
[KEV] Vulnerability in cisco (CVE-2020-3161)
vulnerability in cisco (CVE-2020-3161). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-1653 KEV |
|
[KEV] Vulnerability in Cisco small-business-rv320-and-rv325-routers (CVE-2019-1653)
vulnerability in Cisco small-business-rv320-and-rv325-routers (CVE-2019-1653). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-0296 KEV |
|
[KEV] Vulnerability in Cisco adaptive-security-appliance-asa (CVE-2018-0296)
vulnerability in Cisco adaptive-security-appliance-asa (CVE-2018-0296). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-5591 KEV |
|
[KEV] Vulnerability in Fortinet fortios (CVE-2019-5591)
vulnerability in Fortinet fortios (CVE-2019-5591). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2020-12812 KEV |
|
[KEV] Vulnerability in Fortinet fortios (CVE-2020-12812)
vulnerability in Fortinet fortios (CVE-2020-12812). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2018-13379 KEV |
|
[KEV] Path Traversal in Fortinet fortios (CVE-2018-13379)
path traversal in Fortinet fortios (CVE-2018-13379). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-13608 KEV |
|
[KEV] XXE (XML External Entity) in Citrix storefront-server (CVE-2019-13608)
vulnerability in Citrix storefront-server (CVE-2019-13608). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8193 KEV |
|
[KEV] Vulnerability in Citrix application-delivery-controller-adc (CVE-2020-8193)
vulnerability in Citrix application-delivery-controller-adc (CVE-2020-8193). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8195 KEV |
|
[KEV] Vulnerability in Citrix application-delivery-controller-adc (CVE-2020-8195)
vulnerability in Citrix application-delivery-controller-adc (CVE-2020-8195). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-8196 KEV |
|
[KEV] Vulnerability in Citrix application-delivery-controller-adc (CVE-2020-8196)
vulnerability in Citrix application-delivery-controller-adc (CVE-2020-8196). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|